IP Library Granted Patent US 11,411,990
Granted Patent B2
US 11,411,990 · App. 16/277,468 · Granted Aug 9, 2022

Early detection of potentially-compromised email accounts

Inventors: Ruchika Pandey (Del Mar, CA); Ran Mosessco (Escondido, CA)
Assignee: Forcepoint LLC
H04L63/1483H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,411,990
App. No.
16/277,468
Granted
Aug 9, 2022
Kind
B2
Abstract

A method, system, and computer-usable medium are disclosed for establishing a reference outbound email volume rate for a user account, monitoring the user account to determine a current outbound email volume rate, determining a risk score based on the current outbound email volume rate and the reference outbound email volume rate, buffering outgoing emails of the user account if the risk score exceeds a threshold risk score, analyzing the buffered emails against one or more factors indicative of a probability of the buffered emails comprising spam, and responsive to analysis of the buffered emails against the one or more factors indicating that the user account is potentially compromised, quarantine the user account and prevent outbound mail from being delivered from the user account.

Claims (38)

1. A computer-implemented method for managing network communication, comprising:

establishing a reference outbound email volume rate for a user account;

monitoring the user account to determine a current outbound email volume rate;

determining a risk score based on the current outbound email volume rate and the reference outbound email volume rate;

in response to the risk score exceeding a threshold risk score, buffering subsequent outgoing emails of the user account, wherein the buffering includes delaying delivery of the outgoing emails pending further analysis, and wherein the outgoing emails are not buffered if the risk score does not exceed the threshold risk score;

analyzing the buffered outgoing emails against one or more factors indicative of a probability of the buffered outgoing emails comprising spam; and

responsive to analysis of the buffered outgoing emails against the one or more factors indicating that the user account is potentially compromised, quarantining the user account and preventing outbound mail from being delivered from the user account;

wherein the one or more factors comprises an alphabetization of destination addresses for the buffered outgoing emails, and a measure of the number of destination addresses of the buffered outgoing emails which are freemail accounts.

2. The method of claim 1 , further comprising delivering the buffered outgoing emails responsive to analysis of the buffered outgoing emails against the one or more factors indicating that the user account is not potentially compromised.

3. The method of claim 1 , further comprising allowing delivery of buffered outgoing emails of the user account if the risk score is less than the threshold risk score.

4. The method of claim 1 , wherein the one or more factors comprises a number of unique domains to which the buffered outgoing emails are addressed.

5. The method of claim 1 , wherein the one or more factors comprises a user's use of one or more email clients to send the buffered outgoing emails.

6. The method of claim 1 , wherein the one or more factors comprises a length.

7. A system comprising:

a processor; and

a non-transitory, computer-readable storage medium comprising instructions executable by the processor and configured for:

establishing a reference outbound email volume rate for a user account;

monitoring the user account to determine a current outbound email volume rate;

determining a risk score based on the current outbound email volume rate and the reference outbound email volume rate;

in response to the risk score exceeding a threshold risk score, buffering subsequent outgoing emails of the user account, wherein the buffering includes delaying delivery of the outgoing emails pending further analysis, and wherein the outgoing emails are not buffered if the risk score does not exceed the threshold risk score;

analyzing the buffered outgoing emails against one or more factors indicative of a probability of the buffered outgoing emails comprising spam; and

responsive to analysis of the buffered outgoing emails against the one or more factors indicating that the user account is potentially compromised, quarantining the user account and preventing outbound mail from being delivered from the user account;

wherein the one or more factors comprises an alphabetization of destination addresses for the buffered outgoing emails, and a measure of the number of destination addresses of the buffered outgoing emails which are freemail accounts.

8. The system of claim 7 , the instructions further configured for delivering the buffered outgoing emails responsive to analysis of the buffered outgoing emails against the one or more factors indicating that the user account is not potentially compromised.

9. The system of claim 7 , the instructions further configured for delivery of buffered outgoing emails of the user account if the risk score is less than the threshold risk score.

10. The system of claim 7 , wherein the one or more factors comprises a number of unique domains to which the buffered outgoing emails are addressed.

11. The system of claim 7 , wherein the one or more factors comprises a user's use of one or more email clients to send the buffered outgoing emails.

12. The system of claim 7 , wherein the one or more factors comprises a length of subject lines of the buffered outgoing emails.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

establishing a reference outbound email volume rate for a user account;

monitoring the user account to determine a current outbound email volume rate;

determining a risk score based on the current outbound email volume rate and the reference outbound email volume rate;

in response to the risk score exceeding a threshold risk score, buffering subsequent outgoing emails of the user account, wherein the buffering includes delaying delivery of the outgoing emails pending further analysis, and wherein the outgoing emails are not buffered if the risk score does not exceed the threshold risk score;

analyzing the buffered outgoing emails against one or more factors indicative of a probability of the buffered outgoing emails comprising spam; and responsive to analysis of the buffered outgoing emails against the one or more factors indicating that the user account is potentially compromised, quarantining the user account and preventing outbound mail from being delivered from the user account;

wherein the one or more factors comprises an alphabetization of destination addresses for the buffered outgoing emails, and a measure of the number of destination addresses of the buffered outgoing emails which are freemail accounts.

14. The storage medium of claim 13 , the instructions further configured for delivering the buffered outgoing emails responsive to analysis of the buffered outgoing emails against the one or more factors indicating that the user account is not potentially compromised.

15. The storage medium of claim 13 , the instructions further configured for delivery of buffered outgoing emails of the user account if the risk score is less than the threshold risk score.

16. The storage medium of claim 13 , wherein the one or more factors further comprises at least one of: a number of unique domains to which the buffered outgoing emails are addressed, a user's use of one or more email clients to send the buffered outgoing emails, and a length of subject lines of the buffered outgoing emails.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2019
From: PANDEY, RUCHIKA; MOSESSCO, RAN
To: FORCEPOINT LLC
Reel/Frame 048347/0916 →
Continuity (1)
Related Publication 20200267181A1 · Aug 20, 2020
Cited By (1)
US 12,306,930